CVE-2025-55278

HIGH

HCL DevOps Loop - Auth Bypass

Title source: llm
STIX 2.1

Description

Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentially use expired or tampered tokens to gain unauthorized access to sensitive resources and perform actions with elevated privileges.

Scores

CVSS v3 8.1
EPSS 0.0002
EPSS Percentile 6.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347 CWE-613
Status published
Products (1)
HCL Software/DevOps Loop 1.0.2
Published Nov 05, 2025
Tracked Since Feb 18, 2026